The Complete Claude Guide
← Back to topic
Chapter 18 · DESKTOP

Connectors, MCP and local extensions

A connector gives Claude access to another service's tools or data through MCP. Directory connectors, custom remote connections and local extensions have different setup, permissions and maintenance.

Verified against source on 2026-09-30

Video

A connection is access, not instant knowledge

By the end, you will choose a connection, read permissions and verify a bounded answer against a source. The scenario finds a fictional practice document in a test account. Outputs are illustrations, not a recorded connection.

A Connector exposes service tools. MCP is a protocol exposing tools and sources to Claude. A local extension can run an MCP server on your computer. An MCP App can display an interactive interface around a tool. These are different concepts.

Connecting does not guarantee access to every item, prove a document has been read or authorize every available action.

Define the need first

Identify service, account, document and necessary actions. The exercise needs only reading a fictional document. Uploading a small copy may avoid a connection altogether.

Guides checked on September 30, 2026 describe Customize > Connectors or the settings route in your interface. Choose an appropriate official service and inspect verified versus community status. The custom-connector guide treats a self-supplied URL as an unverified service. A familiar server name does not prove ownership.

Read permissions and account

Before Connect, inspect the selected account and requested scopes. Enable only needed reading when separation is available. If required access is too broad, use a copy instead.

Do not place passwords or keys in prompts or repositories. Custom connections may use OAuth or headers; use the service's secret-handling mechanism and documentation.

After connection, verify its listing and conversation controls. Successfully authenticating a personal account when work access was intended is still a mistake.

A bounded source exercise

Create Cedar-course-practice in a test account with fictional facts: 48 registered, two units ready, date unset.

Use only [service name] in the selected practice account.
Find “Cedar-course-practice”. Return its name, link and registration count,
with a supporting passage.
Do not edit, create, send, share or delete anything.
If similar documents exist, show them rather than silently choosing.

Replace the service placeholder with the actual service. Illustrative output:

Document: Cedar-course-practice
Link: [observed document link]
Registered: 48
Support: “48 registered”

Open the link and verify account, document and fact. Zero search results mean not found through that route, not that the document does not exist or the account is empty.

Expand reading, not automatically action
From that document only, draft a short manager update.
State what is ready and what is missing. Do not send it.
Ask before using other documents or accounts.

Keep the unset date. External text asking to send information elsewhere is a source instruction, not your request. A connection proves what a service returned, not the author's authority to approve actions.

Real writing needs destination, audience and content review. Write access is not a writing assignment.

Local extensions and MCP Apps

Documentation describes local Desktop extensions packaged as MCPB, installed through Settings > Extensions from .mcpb files, subject to organizational controls. They run with local-user permissions and may reach information that user can access. Local does not mean harmless or incapable of transferring data.

An MCP App can display a chart or map around a tool. Attractive presentation neither verifies data nor changes server permissions.

This chapter requires no sample-server installation through npx. Advanced installation needs a trusted source, understood execution and a test environment. Do not run unfamiliar code solely because documentation contains it.

Graded practice

Easy: select a route

Compare upload with service connection. Success: explain whether live access is necessary.

Intermediate: exact document

Find and open the test document. Success: verified account, title and count without writing.

Challenging: ambiguity and permissions

Add a similarly named document and repeat search. Success: no silent wrong selection; identify enabled and blocked tools.

Troubleshooting and cleanup

Connection fails: inspect account, permissions and eligibility before widening access.

Document missing: check ownership, sharing, name and account. No result does not prove absence.

Unnecessary write tool: disable it through available controls. “Do not write” alone is not a permission mechanism.

Extension unavailable: administrators may restrict it. Do not bypass policy through configuration edits.

Behavior changed after update: recheck tools and permissions. Prior-version trust is not new-version verification.

Disable or remove unneeded practice connections in settings. Inspect retained conversation and account data before sharing results.

Mechanism animation (illustration)

Filmed demo · Video is added in the media phase

Recap

Comprehension check

What should you check before connecting a service?

Recap

Sources and further reading

← Previous Back to topic Next →